Guides

KPMG flags 2026 internal audit risks, with AI topping the list

KPMG’s 2026 risk map puts AI, cyber and resilience at the center of audit planning. New IIA requirements make static checklists harder to defend.

Lauren Xu··4 min read
Published
Listen to this article0:00 min
KPMG flags 2026 internal audit risks, with AI topping the list
Photo illustration

The IIA’s Cybersecurity Topical Requirement became effective on February 5, 2026, as KPMG told internal audit teams to stop treating 2026 like a year for broad, equal-weight coverage. Its risk map directs limited resources to the risks that matter most and pairs that warning with a more flexible audit plan that can move as fast as AI, cyber threats, and regulatory change.

AI is moving from pilot work to core audit scope

KPMG’s list places AI and digital disruption near the top of the agenda. By 2029, those risks are expected to become the second most critical area for internal audit. AI is already reshaping business decisions, which means audit teams need to think about governance, ethical scrutiny, model oversight, and the control gaps that appear when automated decisions are embedded in operating processes.

KPMG’s April Future of SOX webcast gives the stronger signal for 2026 planning. About 3,900 audit and risk leaders fed into that discussion, and 70% to 80% said their finance, internal controls, and internal audit functions are still only in pilot or moderate-progress stages on AI enablement. Roughly 26% said lack of time and resources is the biggest obstacle. In practice, that means internal audit should not chase every AI use case at once; the sharper play is to scope a few high-risk areas, such as AI governance, data quality, change management, and how AI changes upstream scoping and testing.

Cyber, data and third-party risk are converging

KPMG’s risk map keeps data governance and privacy, cybersecurity, and supply chain issues in view together, because that is how clients are actually operating. A cloud vendor, a software plug-in, and a data-handling process are no longer separate audit conversations, especially once a control failure in one area can expose the others. The firm’s 2026 audit committee agenda tells committees to clarify their role in oversight of AI, cybersecurity, and data governance, while also helping keep internal audit focused on critical risks beyond financial reporting and compliance.

The IIA’s cybersecurity requirement is now in force, and more mandatory topics arrive later in the year and into 2027, including third-party risk, organizational behavior, and organizational resilience. For audit leaders, that shifts the conversation from whether cyber belongs on the plan to how much evidence, testing, and documentation are needed to show coverage of a mandatory baseline. It also pushes third-party reviews higher on the list, since vendor risk and cyber risk are now hard to separate.

Macro volatility is changing what gets tested

The risk map still includes geopolitical tensions and macroeconomics, regulatory compliance and change, human capital, business continuity and resilience, and organizational governance and corporate reporting. Those are the risks that tend to turn into audit committee questions about estimates, disclosures, workforce capacity, contingency planning, and whether management can keep the control environment steady while the business keeps changing.

KPMG’s Chief Audit Executive Outlook for 2026 puts hard numbers to that backdrop. Based on a December 2025 webcast with more than 1,600 audit and risk leaders, 62% said a recession is likely or already underway, and 25% said they are prioritizing external threats such as cybersecurity and third-party risk. The same material identifies AI as both the No. 1 driver of economic growth and the No. 1 risk on the board’s agenda. For audit scoping, AI is no longer just a technology topic; it is part of the macro story that affects forecasts, controls, and risk appetite.

KPMG’s board agenda also keeps economic pressure in frame by flagging trade duties, geopolitical tensions, sanctions, supply chain disruption, inflation, and market volatility as issues that can flow straight into financial reporting and internal controls. Internal audit tests whether management’s assumptions, estimates, and disclosures can survive a more volatile operating environment.

What changes in the 2026 plan

The practical shift is not to add every new risk as a separate workstream. It is to build one flexible plan that keeps the old risks covered while reserving capacity for the new ones that are moving fastest. KPMG points audit teams toward a dynamic plan, and the IIA’s mandatory topical requirements make that flexibility less optional than it used to be.

  • Put AI governance and digital disruption on a named audit track, even if the work begins with narrow pilots rather than broad enterprise testing. In KPMG’s Future of SOX webcast, most teams are still early in the journey, so the near-term win is control clarity, not automation theater.
  • Combine cyber, data governance, and third-party risk into one planning lens where possible. The IIA’s February 5 cybersecurity requirement is already in force, and the upcoming third-party requirement gives audit teams a deadline for tightening vendor-related testing.
  • Keep sustainability reporting, organizational governance, and business continuity on the committee agenda, but test them through concrete control questions rather than broad policy reviews. These topics belong in the oversight conversation alongside financial volatility and regulatory change.
  • Use resource allocation as the filter. KPMG’s risk map puts the capacity constraint up front, so the right question for each assignment is whether it materially changes the organization’s understanding of risk and control, not whether it fills a slot on a legacy calendar.

This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.

Did this article answer your question?

Discussion

More KPMG News